#threatintel and #dfir lead @ PwC. Blue team forever. Christian, husband, dad, coffee addict, bad photographer, awful cyclist. Tweets my own, not PwC's.
this meeting could have been an MCP invoked search of our company’s internal knowledge base that aggregates data from virtually every service we use behind a unified retrieval layer and provides a streamlined interface for extracting critical business insights
This is an interesting trend worth mentioning. People are processing threat intelligence blogs using AI and republishing summaries and often improved analysis with additional IOCs and YARA rules. These are not always good. 🧵
Today, the UK and partners have exposed Russian state-supported actors LAUNDRY BEAR for a phishing campaign targeting Western organisations.
Act now to mitigate the threat⬇️
https://t.co/VEsZqFhLgc
ICYMI: the State of Statecraft conference (@what_is_sos) returns to Brussels for Volume II on October 22, 2026. Registration is open & the CFP runs until Aug. 14
SOS is an event focused on state-sponsored operations: https://t.co/dPROolOxy9
🧵👇
If you are dealing with incidents and want quick analysis of which VS Code Extensions are installed, you need to run custom scripts. EDRs most often lack inventories/visibility here.
Sharing a PS1 script to collect all installed extensions from a device.
https://t.co/dZA9Tj7a8D
On Day 2 of CYBERUK, the NCSC and 15 international partners have issued new guidance to help organisations better defend against activity originating from China-linked covert networks. 🌍 🚨
Find out more⬇️
https://t.co/lFdirgCRiw
Excited to support @pivot_con again! This year we're hosting a workshop on hunting phishing pages & pivoting across infrastructure. If you're attending, come find us - we'd love to catch up with familiar faces and hear your stories! https://t.co/951jcmuUgI
There is no easy 'just do' in response to the surfacing of latent vulnerability in technology.
Vendors must make the investment to address, test and then release.
Customers then need to patch.
There is no magic - just a sequence of events which now need to take place..
📣#PIVOTcon26 Agenda is here 🤟 We are thrilled to announce the lineup for this year's speaker lineup.
2⃣days and 19 talks from leading #ThreatResearch experts.
The agenda link is in the first comment👇, and the talks and speakers are in the thread.🧵
#CTI#ThreatResearch
1/15
Exploitation of Cisco Catalyst SD-WAN
Agencies strongly encourage immediate investigation of potential compromise of Cisco Catalyst SD-WAN, and full updating and hardening.
https://t.co/7G29CHJk1g
There’s no need to suffer through the rough patch of indeterministic Claude Code behaviors. Here’s my config to get you started w proper planning, implementation, and review, phased development, decision point documentation, git worktrees, and consensus deep research implemented w deterministic hooks. It’s a WIP. Hope it helps!
https://t.co/qMKnYETonN